Cyber Resilience

Threat actor · all actors

WIRTEG0090 unknown

aka WIRTE, Ashen Lepus

Last updated: 2026-07-03

0attributed CVEs
42ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[WIRTE](https://attack.mitre.org/groups/G0090) is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. [WIRTE](https://attack.mitre.org/groups/G0090) has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. [WIRTE](https://attack.mitre.org/groups/G0090) has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.(Citation: Lab52 WIRTE Apr 2019)(Citation: Kaspersky WIRTE November 2021)(Citation: Check Point Wirte NOV 2024)(Citation: Palo Alto Ashen Lepus DEC 2025)

Source: MITRE ATT&CK

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-426 / 4262%
CM-623 / 4255%
SI-323 / 4255%
CM-222 / 4252%
CA-718 / 4243%
CM-716 / 4238%
AC-415 / 4236%
SI-715 / 4236%
SC-713 / 4231%
SI-1013 / 4231%
AC-311 / 4226%
SI-211 / 4226%
AC-610 / 4224%
AC-29 / 4221%
IA-97 / 4217%

Co-occurring actors

None.

Similar actors

Similar TTPs